Description
OWASP Security Testing of Web, API, Android & Source code app course. This course offers a fully practical and applicable training program. Combining basic theoretical concepts with practical exercises based on real vulnerable applications and industry standard tools, this course provides a comprehensive path to mastering web and API application security. The course topics start with understanding web architecture and HTTP protocols and examine in detail the vulnerabilities on the OWASP top ten list. Participants will be introduced to API types including REST and SOAP, as well as essential security testing techniques using professional tools such as Burp Suite, Vooki, Yazhini, Nmap/Zenmap and Snyk. This course teaches how to simulate attacks, identify security weaknesses and understand the performance of enterprise applications at different layers including the user interface, business logic layer and database. Another part of the course is dedicated to setting up and working with popular and intentionally vulnerable applications such as OWASP Juice Shop and Web Goat. With an emphasis on experiential learning, this course covers web and API topics, as well as security testing Android APK files and scanning the source code of open source projects for vulnerabilities. The ultimate goal of this course is to provide learners with the skills and confidence to understand, identify, and remediate security flaws in modern applications.
What you will learn
- Understand the principles of Web Client-Server architecture and three-tier enterprise application models.
- Learn what APIs are, their structure, and how REST and SOAP APIs work in real-world systems.
- Gain in-depth knowledge of HTTP/HTTPS protocols, headers, cookies, and request-response cycles.
- Explore and analyze OWASP Top 10 web and API vulnerabilities through hands-on, real-time exercises.
- Launch and test popular vulnerability applications such as OWASP Juice Shop, Web Goat, Parabank, and more.
- Perform port scanning using Nmap/Zenmap to discover open, filtered, and closed ports.
- Install and use Burp Suite to perform manual security testing and penetration testing.
- Capture, intercept, and manipulate HTTP requests/responses using Burp tools like Proxy, Repeater, Intruder.
- Scan REST and SOAP APIs for vulnerabilities using the Vooki security testing tool.
- Testing Android APK files for security flaws using Yazhini, Dex2Jar, and JD-GUI.
- Scan open-source code repositories for vulnerabilities using Snyk and interpret SAST reports.
- Generate detailed security testing reports for websites, APIs, and Android apps.
This course is suitable for people who:
- Manual and automated testers who want to expand their practice into security testing.
- Quality Assurance Engineers (QA Engineers) interested in learning API security and web vulnerability assessment.
- Beginners in cybersecurity who are looking for practical, hands-on experience.
- Developers who want to understand common security flaws in web and API implementations.
- Students or recent graduates looking to build a strong foundation in web application security.
- Anyone preparing for roles such as security tester, penetration tester, or ethical hacker.
- Trainers and instructors looking to deliver real-time security concepts and tools.
Course details: Learn how to use MCP (Model Context Protocol)
- Publisher: Udemy
- Instructor: Kumar Gupta, Isha Training Solutions , Anand Kumar Gupta , Kiran G
- Training level: Beginner to advanced
- Training duration: 22 hours and 33 minutes
- Number of lessons: 26
Course headings

OWASP Security Testing of Web API Android & Source code app course prerequisites
- Basic understanding of how web applications work (client-server model is helpful)
- Familiarity with software testing or QA concepts (not mandatory but recommended)
- No prior knowledge of security testing required – all tools and concepts are explained from scratch
- A Windows/Linux machine with internet access to install and run security testing tools
- Willingness to learn through hands-on practice using real-world vulnerable applications
Course images

Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
Download link
Downloadly
Rapidgator link
File(s) password: www.downloadly.ir
File size
9.4 GB